Artifact GuideGLOBALETSI EN 319 411-2

ETSI EN 319 411-2 How should qualified trust service providers handle revocation under ETSI EN 319 411-2

A standalone answer for qualified trust service teams translating ETSI EN 319 411-2 revocation clauses into CPS procedures, status publication, and audit evidence.

Based on external standards and official source URLs. Use it as implementation guidance, not for legal interpretation.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

A QTSP must control the full path from request to published status. The CPS should identify authorized requesters, authentication and confirmation rules, publication timing, or behavior, and the method used to preserve status beyond certificate expiry.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What should revocation procedures cover?

ETSI EN 319 411-2 makes the EN 319 411-1 request controls applicable to qualified certificate services. In practice, the QTSP's CPS should define who can submit revocation requests or event reports, how they are submitted, when confirmation is required, what reasons can lead to suspension or revocation, and which mechanism distributes revocation status information. The procedure should separate a request from an event report: both need intake and authorization controls, but the party reporting a key compromise or policy breach may not be the subscriber asking for revocation.

The timing control is concrete: EN 319 411-1 requires the actual certificate status change to be available to relying parties no later than 24 hours after receipt of the or suspension request. If confirmation cannot be completed within that window, the CPS needs an exception procedure and the QTSP must record the actions taken and justification. Under eIDAS Article 24(3), revocation takes effect immediately when the published status changes.

  • Authenticate each request or event report and check that it comes from an authorized source before changing certificate status.
  • Process requests and revocation-related event reports on receipt, with UTC-synchronized time used for the revocation service.
  • Apply the 24-hour maximum delay to every status method in use when both and can lag.
  • Branch explicitly between rejection, temporary suspension where legally available, and permanent ; record the reason, decision authority, effective publication time, notifications, and affected status mechanisms.
Citations
Question 2

What evidence should support revocation under ETSI EN 319 411-2?

Evidence should show that the QTSP can receive, authenticate, decide, publish, and preserve status consistently for the qualified certificate profiles it issues. Follow the sequence from the request or event report through the certificate database update and or publication.

For revoked or suspended certificates, keep enough records to prove the received request time, authorization check, confirmation or exception path, decision time, certificate-database update, status publication time, and notification to the subject or subscriber where possible. Article 24(4) requires per-certificate information to be automated, reliable, free of charge, efficient, available at any time, and available beyond validity. Reconcile the source ticket, database, , response, and subscriber notice so their certificate identifier, reason, and timestamps agree.

  • CPS extracts covering request submitters, submission channels, confirmation rules, suspension or revocation reasons, or distribution, and maximum delays.
  • Timestamped tickets or logs showing receipt, authorization, confirmation status, decision, certificate database update, or publication, and any 24-hour exception justification.
  • Status-service evidence showing 24/7 availability, integrity and authenticity protections, and consistent updates across and when both are used; if the certificates are publicly trusted, also preserve evidence that the required information is publicly and internationally available.
Citations
Question 3

What checklist should teams use for revocation under ETSI EN 319 411-2?

Use a checklist that follows the certificate lifecycle clauses. The review should prove that requests and event reports are controlled, suspension is separated from permanent , revoked certificates are not reinstated, and relying parties can obtain status information through the published mechanisms. Repeat the review after a policy or status-service change, key compromise, QSCD status change, CA termination, failed publication, or missed 24-hour deadline.

  • Map each qualified certificate profile in scope to its request process, including authorized submitters, confirmation rules, future-dated requests, emergency reasons, and UTC time source.
  • Verify that non-expired certificates are revoked when they are no longer compliant with the applicable certificate policy, when known changes affect certificate validity, or when the cryptography no longer ensures the binding between subject and public key.
  • Check handling where CRLs are used: publication at least every 24 hours until the last CRL, nextUpdate values, signer, expired revoked certificate handling, and last-CRL preservation.
  • Check handling where OCSP is used: ArchiveCutOff is recommended, last OCSP answers are optional where the CA certificate is about to expire, and the CPS must explain how to interpret temporary differences between OCSP and .
Citations
Primary sources

References and citations

Related guides

Explore more topics

eIDAS QTSP supervision workflow for ETSI EN 319 411-2
Operational workflow for qualified trust service providers using ETSI EN 319 411-2 to manage supervisory-body changes, incidents, termination evidence, trusted-list checks, and assessment records.
ETSI EN 319 411-2 certificate operations
Operational guide for ETSI EN 319 411-2 qualified certificate services: policy identifiers, identity validation, issuance, QSCD handling, revocation status, and relying-party notices.
ETSI EN 319 411-2 compliance checklist
Compliance checklist for ETSI EN 319 411-2 qualified certificate services, covering policy selection, CP/CPS evidence, identity validation, QSCD status, trusted-list reliance, and certificate status services.
ETSI EN 319 411-2 FAQ for EU Qualified Certificates
Answers to common ETSI EN 319 411-2 questions about EU qualified certificate policies, QSCD use, identity validation, trusted lists, and revocation status services.
ETSI EN 319 411-2 Identity Proofing
How EN 319 411-2 applies identity validation for EU qualified certificates, including QCP natural-person, legal-person, website, and evidence-record checks.
ETSI EN 319 411-2 profile selector
Select the right ETSI EN 319 411-2 qualified certificate policy profile for signatures, seals, QSCD use, and website authentication.
ETSI EN 319 411-2 QSCD Route
When QCP-n-qscd or QCP-l-qscd is the right EN 319 411-2 route, what QSCD evidence is needed, and which certificate-profile claims must stay aligned.
ETSI EN 319 411-2 QTSP supervision evidence workflow
Build an assessment-ready QTSP supervision evidence pack for ETSI EN 319 411-2 qualified certificate services, covering policy identifiers, trusted-list checks, incident records, QSCD evidence, and termination controls.
ETSI EN 319 411-2 Qualified Certificate Scope
Use ETSI EN 319 411-2 to scope EU qualified certificate services by certificate policy, subject type, QSCD use, website authentication profile, and eIDAS context.
ETSI EN 319 411-2 requirements map
Map ETSI EN 319 411-2 requirements for EU qualified certificate services across QCP profiles, CP/CPS documentation, QSCD use, certificate profiles, revocation, and eIDAS Annex A references.
ETSI EN 319 411-2 trusted-list evidence
Build EN 319 411-2 trusted-list evidence for EU qualified certificate reliance: relying-party notice text, QTSP service identifiers, validation records, and change triggers.
ETSI EN 319 411-2 trusted-list validation workflow
Validate an EN 319 411-2 EU qualified-certificate claim by mapping the certificate service to the QTSP trusted-list entry, policy profile, relying-party notice, and status evidence.
ETSI EN 319 411-2 vs eIDAS Qualified Trust Services
Compare ETSI EN 319 411-2 certificate policy requirements with the eIDAS qualified-status, supervision, audit, and trusted-list framework.
ETSI EN 319 411-2 vs EN 319 411-1
Compare ETSI EN 319 411-2 EU qualified certificate requirements with EN 319 411-1 general certificate-service requirements, including policy inheritance, QSCD controls, and CP/CPS evidence reuse.
ETSI EN 319 411-2: end-to-end qualified certificate lifecycle management workflow
Lifecycle workflow for ETSI EN 319 411-2 qualified certificate services, from policy selection and identity validation through issuance, renewal, re-key, modification, revocation, status services, and records.
ETSI EN 319 411-2: Legal vs Natural Person Certs
ETSI EN 319 411-2 separates qualified certificate policies for natural persons, legal persons, QSCD use, and website authentication subscribers.
ETSI EN 319 411-2: QCP, QNCP, and QEVCP Profile Selection
Choose the right ETSI EN 319 411-2 qualified certificate policy profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
How should QTSPs select an ETSI EN 319 411-2 qualified certificate profile?
A focused FAQ on choosing QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen under ETSI EN 319 411-2.
How should relying parties use trusted lists under ETSI EN 319 411-2?
FAQ on EN 319 411-2 trusted-list reliance for EU qualified certificates: relying-party notices, QTSP service identifiers, validation evidence, and source references.
QSCD Requirements in ETSI EN 319 411-2
How ETSI EN 319 411-2 treats QSCD-backed qualified certificates, including QCP-n-qscd and QCP-l-qscd policies, key-use controls, QSCD verification, and certificate profile evidence.
QTSP Supervision and ETSI EN 319 411-2
How ETSI EN 319 411-2 supports QTSP supervision evidence for qualified certificate services, trusted-list reliance, liability responsibility, incident records, and audit preparation.
Qualified certificates under ETSI EN 319 411-2
FAQ answer for QTSPs on how ETSI EN 319 411-2 treats EU qualified certificates, policy identifiers, QSCD variants, website certificates, and lifecycle evidence.
What are the qualified certificate policies in ETSI EN 319 411-2?
FAQ on ETSI EN 319 411-2 qualified certificate policies, including QCP-n, QCP-l, QSCD variants, QEVCP-w, QNCP-w, and policy identifiers.
Which QWAC Profile Fits ETSI EN 319 411-2?
Choose between QEVCP-w, QNCP-w, and QNCP-w-gen for qualified website authentication certificates under ETSI EN 319 411-2.